Blog
Ángulo de sprinto a la derecha
Producto
Ángulo de sprinto a la derecha
November 2025 Product Updates: Automate More, Map Wider, and Close Compliance Gaps Faster

November 2025 Product Updates: Automate More, Map Wider, and Close Compliance Gaps Faster

Compliance issues pile up across monitors and checks, and resolving them still means manually investigating each one, identifying the fix, and logging the outcome. Mapping controls across multiple standards creates duplicated records and rework every time a new framework enters scope. Evidence collection for systems without native integrations forces teams to toggle between cloud consoles, take screenshots, and upload them manually with no timestamp or traceability. Risk registers describe threats in isolation, disconnected from the vendors, devices, and systems they actually affect. Policies written months ago drift from the controls and workflows they reference, and the mismatch only surfaces when an auditor flags it.

Las últimas actualizaciones de Sprinto están diseñadas para solucionar precisamente eso. Ahora puedes:

  • Resolve compliance issues and answer questionnaires through Sprinto AI Agents with 25+ custom agent workflows
  • Map every Sprinto object to any external standard with Infinite Frameworks
  • Capture timestamped evidence directly from cloud consoles using the Sprinto Extension
  • Link vendors, devices, findings, and policies directly to risks for live risk context
  • Detect and fix policy drift with side-by-side comparisons and one-click updates
  • Sync cloud services, HRMS, and SaaS tools automatically through Integration Agents
  • Automate background verification evidence with the OnGrid integration
  • Run AI Actions in bulk across policies, risks, and questionnaires
  • Navigate a unified entity detail layout across People, Access, and Infra modules
  • Pull IAM evidence and device posture data from JumpCloud
  • Sync Jira assignee, reporter, and attachment metadata into Sprinto drawers
  • Retrieve Trust Center documents in bulk with a redesigned, customizable interface

Lea a continuación información detallada sobre estas actualizaciones:

1. Resolve compliance issues and accelerate audit workflows with AI Agents

You can now use Sprinto AI Agents to detect compliance issues, suggest and execute fixes, and respond to questionnaires, replacing manual investigation and resolution cycles that slow down audit preparation.

Sprinto AI Agents operate across compliance operations, identifying issues within your monitors and checks, then recommending or directly executing the appropriate fix. Over 60 organizations are already running AI Agents, with 25+ custom agent workflows active across different compliance programs. These agents work within your existing Sprinto environment, processing issues and questionnaire responses in the context of your controls, frameworks, and evidence.

The automation covers detection, suggestion, and execution in a single flow. When an agent identifies an issue, it evaluates the compliance context, proposes a resolution, and can carry out the fix without requiring your team to switch tools or manually log the action.

¿Por qué es importante?

AI Agents reduce the volume of manual audit work your compliance team handles day to day. By automating issue detection and resolution, response cycles shorten and your team spends less time on repetitive investigation.

The compounding effect matters most at scale. Organizations running multiple frameworks or preparing for concurrent audits can maintain ongoing compliance readiness without proportionally increasing headcount. Each resolved issue is logged with full context, improving the traceability auditors expect.

2. Map any standard to any Sprinto object with Infinite Frameworks

You can now create framework-agnostic mappings for all policies, checks, and risks in Sprinto, connecting your existing compliance objects to any external standard, whether regulatory, industry-specific, or customer-driven.

Infinite Frameworks lets your team define flexible cross-framework relationships across every Sprinto object. If a customer sends you a custom security questionnaire that maps to specific controls, or a regulator publishes a new standard, you can map your existing policies, checks, and risks directly to those requirements. The mapping works across multiple standards simultaneously, so a single control can satisfy requirements from SOC 2, ISO 27001, and a customer-specific framework without creating separate records for each.

This removes the need to duplicate controls, policies, or risk entries when a new framework enters scope. Your team builds mappings on top of the compliance structure you already have.

¿Por qué es importante?

Multi-framework organizations typically duplicate controls and policies every time they add a new standard. Infinite Frameworks eliminates that rework by letting one Sprinto object serve multiple standards at once.

Consider a team managing SOC 2, ISO 27001, and a sector-specific regulation. Previously, adding the third framework meant recreating mappings from scratch. Now, your team maps existing objects to the new standard directly, preserving all prior evidence and control linkages. The result is a single, evolving compliance structure that adapts as requirements change.

3. Capture live evidence from any web application with the Sprinto Extension

You can now capture screenshots and configuration evidence directly from cloud consoles and web applications using the Sprinto Extension, eliminating the need to switch between tools, manually save files, or re-upload evidence into your compliance platform.

The Sprinto Extension is a browser extension that lets you capture evidence in real time while working inside any cloud console or web app. Each capture is validated, timestamped, and stored directly in Sprinto, creating traceable proof that auditors can verify without requesting additional context. Your team no longer needs to save screenshots locally, rename files, or manually tag them before uploading.

Evidence captured through the extension carries timestamp and source metadata automatically, making it immediately usable for audit reviews.

¿Por qué es importante?

Scattered screenshots stored in shared drives or local folders create gaps in audit trails. The Sprinto Extension ensures every piece of evidence is captured at the source, validated, and stored in the same platform where your controls and checks live.

For systems that lack native Sprinto integrations, such as niche SaaS tools or internal admin consoles, the extension provides a structured way to collect evidence without building a custom integration. Your team captures what they need during their normal workflow, and auditors see timestamped, traceable proof tied directly to the relevant control.

You can now link vendors, digital systems, policies, findings, and devices directly to individual risks in Sprinto, turning static risk registers into dynamically updated records that reflect your actual operational environment.

Entity-level risk linkage lets your team connect any Sprinto asset to a risk record. When a linked vendor’s status changes, a device falls out of compliance, or a finding is logged against a system, the associated risk record reflects that change automatically. This creates traceability between risk assessments and the real assets they describe, without requiring manual updates to risk registers.

Supported entity types include digital systems, findings, vendors, and devices. Each linkage is visible within the risk record, giving reviewers immediate context on what assets are affected and how.

¿Por qué es importante?

Risk assessments that exist only as text descriptions, disconnected from the systems and vendors they reference, lose accuracy over time. Linking assets directly to risks ensures that your risk posture updates as your environment changes.

A practical example: if a vendor linked to a data-processing risk fails a security review, your risk record surfaces that change immediately. Your team can prioritize remediation based on real signals, and auditors see a risk register grounded in live operational data.

5. Detect and resolve policy drift before auditors do

You can now identify inconsistencies between your policies, automated checks, and framework requirements using Policy Drift Detection, which flags mismatches and provides side-by-side comparisons with recommended updates.

Sprinto scans across your framework mappings, automated checks, and workflows to detect where policy language has drifted from your actual controls. When drift is detected, the system presents a side-by-side view of your existing policy content alongside recommended changes. Your team can review the comparison and apply updates with a single click, keeping documentation aligned with operational reality.

Drift flags cover multiple sources: framework requirement changes, updates to automated checks, and workflow modifications. This means your policies stay current even as your compliance program evolves across review cycles.

¿Por qué es importante?

Policy mismatches are one of the most common audit findings. A policy that describes a quarterly access review while your automated check runs monthly creates a gap that auditors will flag. Policy Drift Detection surfaces these inconsistencies before a review begins.

By providing one-click updates with suggested improvements, Sprinto reduces the time your team spends on manual policy reviews and version comparisons. Policy owners can resolve drift in minutes, and the update history provides a clear trail showing when and why each change was made.

6. Keep compliance data current across all systems with Integration Agents

You can now sync cloud services, HR systems, and SaaS tools to Sprinto through Integration Agents, which automate event-driven data syncing and eliminate manual export and import cycles.

Integration Agents provide a unified connection layer that continuously syncs security and configuration data from your third-party tools into Sprinto. The syncing is event-driven, meaning changes in your source systems, such as a new employee added in your HRMS or a configuration change in a cloud service, flow into Sprinto automatically. Evidence, controls, and risk posture data stay up to date without manual intervention.

The unified connection model reduces setup complexity. Your admins and engineers configure the integration once, and the agent handles ongoing synchronization across cloud, HRMS, and SaaS environments.

¿Por qué es importante?

Stale compliance data undermines audit readiness. When your HRMS shows an employee offboarded last week but Sprinto still lists them as active, your access controls appear incomplete. Integration Agents ensure that your compliance posture reflects real activity across all connected systems.

For engineering and IT teams, the value is reduced maintenance. A single connection layer replaces the need to manage individual sync jobs, export schedules, or manual data reconciliation across multiple tools.

7. Automate background verification evidence with the OnGrid integration

You can now connect OnGrid as a background verification provider in Sprinto, syncing BGV status and results directly into your compliance records through an API-based integration.

The OnGrid integration uses Client ID, Secret, and Community ID credentials for onboarding. Once connected, BGV status and verification results sync into Sprinto automatically, with support for two check types and full evidence handling. Verification outcomes are stored alongside your other HR compliance evidence, creating a single location for all personnel-related documentation.

¿Por qué es importante?

Background verification records often live in a separate vendor portal, disconnected from the compliance platform where auditors review HR controls. The OnGrid integration brings BGV evidence into Sprinto, making it accessible alongside onboarding records, access provisioning data, and policy acknowledgments.

This is particularly valuable during SOC 2 or ISO 27001 audits where HR audit traceability is a control requirement. Your team no longer needs to export BGV reports from OnGrid and manually upload them. The integration handles synchronization, and auditors see verification results in context.

8. Review and enhance multiple records at once with Bulk AI Actions

You can now run any AI Action, whether Sprinto-built or custom, across multiple policies, risks, or questionnaires simultaneously, replacing the need to process records one by one.

Bulk AI Actions let your team select a set of records and execute an AI Action across all of them in parallel. Whether you are reviewing risk descriptions for completeness, enhancing policy language for a framework update, or processing questionnaire responses, the bulk execution handles all selected records in a single operation. Results are available for download or record-by-record inspection after processing completes.

¿Por qué es importante?

Editing and reviewing compliance records individually does not scale. A team managing 40 policies across two frameworks can now run an AI-powered review across all of them in one action, identifying gaps or suggesting improvements without opening each record separately.

This is especially useful during audit preparation, when large volumes of documentation need to be reviewed and updated within a tight window. Bulk AI Actions compress review cycles from hours to minutes, and the parallel processing ensures consistency across all records in the batch.

9. Navigate entity details faster with a unified layout across Sprinto

You can now work with a standardized entity detail panel across People, Access, and Infra modules, replacing the previously inconsistent navigation patterns that slowed down reviews and troubleshooting.

The redesigned detail panel introduces a unified layout and interaction model. Every entity type now opens in a full-width view with instant metadata visibility, so your team sees the same structure whether they are reviewing a person’s access permissions, an infrastructure asset’s configuration, or an application’s compliance status. Backend enhancements improve load times and data clarity across all entity drawers.

¿Por qué es importante?

When navigation patterns differ between modules, your team spends cognitive effort relearning where information lives each time they switch contexts. A unified layout eliminates that overhead and makes cross-module reviews, such as tracing an access issue from a person to an infrastructure asset, significantly faster.

For teams conducting access reviews or incident investigations that span multiple entity types, the consistent layout reduces the time spent locating metadata and accelerates decision-making during time-sensitive workflows.

10. Automate IAM evidence collection with the JumpCloud integration

You can now pull IAM evidence and device posture data from JumpCloud into Sprinto, automating identity and access management evidence collection that previously required manual exports.

The JumpCloud integration syncs user accounts, access details, and device metadata into Sprinto automatically. Device posture signals are mapped to compliance checks, giving your team visibility into endpoint compliance alongside identity data. Full metadata from JumpCloud appears directly inside Sprinto drawers, so reviewers can inspect IAM evidence without switching to the JumpCloud console.

¿Por qué es importante?

IAM evidence collection is a recurring, manual task for teams using directory services that lack a native Sprinto integration. The JumpCloud integration automates user and device data syncing, eliminating manual account reporting and screenshot-based evidence gathering.

For organizations running access audits, the integration provides end-to-end IAM policy and access evidence within Sprinto. Auditors can verify user provisioning, access levels, and device compliance from a single platform, reducing back-and-forth requests during the review.

11. Strengthen incident and change audit trails with richer Jira metadata

You can now pull assignee and reporter fields, along with file attachments, from Jira records directly into Sprinto, making incident and change management evidence more complete and audit-ready.

The enhanced Jira integration automatically syncs assignee and reporter metadata for all Jira records linked to Sprinto. Attachments associated with Jira issues are also pulled in automatically, so supporting documents, screenshots, and logs appear inside Sprinto drawers without manual uploads. Traceability for each record is available directly within the entity detail view.

¿Por qué es importante?

Incident and change management controls require clear accountability: who reported the issue, who was assigned to resolve it, and what supporting evidence exists. Previously, teams needed to manually upload Jira attachments and note assignee details in Sprinto. The enhanced sync handles this automatically.

During an audit, an auditor reviewing a change management control can now see the full chain from reporter to assignee to resolution, with all attachments, inside Sprinto. This eliminates requests for supplementary evidence and strengthens the audit trail for every Jira-sourced record.

12. Present a more professional and navigable Trust Center to external reviewers

You can now offer a redesigned Trust Center experience with bulk document access requests, persistent overview panels, fast document navigation from framework and resource cards, and visual customization options including solid colors, images, and gradients.

The Trust Center redesign introduces bulk access requests, allowing external reviewers to retrieve all available documents in a single action. A persistent overview panel stays visible across all Trust Center pages, giving visitors consistent context as they navigate. Framework and resource cards provide direct links to relevant documents, reducing the number of clicks needed to find specific compliance material. Your team can also customize the Trust Center appearance with solid color backgrounds, uploaded images, or gradient styles.

¿Por qué es importante?

Your Trust Center is often the first compliance touchpoint for prospects and customers. A slow, cluttered interface that requires individual document requests creates friction during security reviews and slows down sales cycles.

With bulk access requests and faster navigation, external reviewers complete their due diligence more quickly. The customization options let your team present a Trust Center that reflects your brand, while the persistent overview panel ensures visitors always understand what compliance material is available.

Sprinto’s November 2025 Updates: Automate More, Map Wider, and Close Compliance Gaps Faster

With these updates, your team can resolve failing checks and complete questionnaires through AI Agents in autonomous workflows that compress days of manual triage into minutes, absorb a new regulatory standard into Infinite Frameworks by mapping existing controls directly without recreating a single record, capture audit-grade evidence from any web application during normal work through the Sprinto Extension, reflect live vendor and device status in risk registers through direct entity linkage, and close policy documentation gaps with Policy Drift Detection’s suggested rewrites that policy owners accept in one click.

These updates give compliance and security teams the tools to run multi-framework programs, prepare for concurrent audits, and maintain a continuously accurate risk posture without scaling headcount to match.

Srikar Sai
Autor

Srikar Sai

Como especialista sénior en marketing de contenidos en Sprinto, Srikar Sai cree que el buen contenido debería ser digno de guardar en favoritos por defecto. Escribe sobre ciberseguridad y GRC, con el objetivo de generar un impacto positivo con cada artículo. Además, es auditor líder certificado según la norma ISO 27001.
¿Cansado del contenido superfluo sobre GRC y ciberseguridad? Suscríbete a nuestro boletín y obtén información detallada.
Investigaciones y análisis seleccionados para ayudarte a ganarte un lugar en la mesa.
imagen de pie de página de blog único